Privacy
This page says what Bushido XYZ d.o.o. does with the personal data that bshdo.co touches, in plain words. It is short because the site does little: a contact form, a booking calendar, one analytics tag, and two embeds that wait for your say-so.
Last updated 10 October 2026.
We are the controller for everything described here.
We have no data protection officer; the law does not ask one of a company our size doing this kind of work. The address above reaches the people who run the site.
When you write to us. The form on the contact page asks for your name, your email, your company, where the product stands and what you want to tell us. It goes through Formspark, a form service, which forwards it to our inbox and keeps a copy. If the form fails, your email client opens instead and nothing passes through Formspark. We use what you send to answer you and to prepare the call. The legal basis is the steps you ask us to take before a contract, or our legitimate interest in replying to someone who wrote to us. We keep the conversation while it is open and for up to two years after our last exchange. If we end up working together, the engagement agreement takes over.
When you book a call. Booking runs on Calendly, on our contact page or on Calendly’s site. It asks for your name, your email, your time zone and the slot, plus whatever you add. Calendly processes it for us and the booking lands in our calendar, where it stays. Same purpose and basis as the form.
When you visit. The site is static and served by Cloudflare. To deliver pages and to block abuse, Cloudflare sees your IP address and the headers your browser sends, and holds them briefly in its logs. We keep no server logs ourselves. The basis is our legitimate interest in running a site that stays up.
Analytics, only if you allow it. With your consent, Google Analytics records the pages you read, the buttons you click, how you arrived, your browser and device, and a rough location worked out from your IP address, which Google uses for that and does not store. We look at totals, not at people: which pages help, which calls get booked. The tag turns Google Signals and advertising features off, and we never link it to advertising. If you refuse, no analytics cookie is set; the tag still sends Google a cookieless ping, and what we see is an estimate. The basis is your consent, which you can withdraw from the footer at any time. Google holds the raw events for at most 14 months.
Embeds, only if you allow them. The booking calendar on the contact page is Calendly’s, and the review badge in the footer is Clutch’s. Each is loaded from the vendor’s servers and sets its own cookies once it appears, so neither loads until you allow embeds. Until then the calendar is a link that opens in a new tab, and the badge is a plain link to our profile.
That is the whole list. There are no accounts, no payments, no newsletter and no advertising. We do not profile anyone and make no automated decisions about you.
Four cookies at most, in three groups. The first asks nothing of you; the other two wait for your choice.
| Name | Group | Set by | Lasts | Purpose |
|---|---|---|---|---|
| bshd_consent | Necessary | bshdo.co | 6 months | Remembers your choice here |
| _ga | Analytics | bshdo.co, read by Google | 2 years | Tells one visitor from another |
| _ga_* | Analytics | bshdo.co, read by Google | 2 years | Keeps one visit together |
| Calendly’s and Clutch’s own | Embeds | calendly.com, clutch.co | Set by the vendor | Run the calendar and the review badge |
Your browser can delete any of them, and the card you saw on your first visit is one click away:
Only the services that make the site work, each under its own data processing terms and only for the job named above:
We do not sell personal data and share none of it for advertising. We hand it to an authority only when the law obliges us to.
We are in Serbia. Most of the services above are in the United States, some with servers in the European Union. For visitors in the EU and the UK, those transfers rest on the standard contractual clauses the GDPR and the UK GDPR recognise, and on the EU-US Data Privacy Framework where the provider is certified under it. Serbian law takes the same approach.
Wherever you are, you can ask us what we hold about you, have it corrected or deleted, ask us to stop or limit using it, object to our legitimate interests, take a copy with you, and withdraw any consent you gave. Write to vision@bshdo.co. We answer within 30 days and may ask you to confirm who you are first.
If our answer does not satisfy you, you can complain to a supervisory authority: in Serbia the Commissioner for Information of Public Importance and Personal Data Protection, in the EU the authority of your country, in the UK the Information Commissioner’s Office.
The site is for businesses; we do not knowingly collect anything from anyone under 16. Everything travels over HTTPS, nothing is stored on servers of ours, and the inbox is reachable by the people who need it. When this page changes, the date at the top changes with it; if the change matters, we say so here.
Shaped on the GDPR privacy policy template that General Legal published under CC0.